Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-6068 |
|
Use-After-Free in nasm (CVE-2026-6068)
vulnerability in nasm (CVE-2026-6068). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33092 |
|
Vulnerability in privilege-escalation (CVE-2026-33092)
vulnerability in privilege-escalation (CVE-2026-33092). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39304 |
|
Vulnerability in activemq (CVE-2026-39304)
vulnerability in activemq (CVE-2026-39304). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.4, 6.2.4` or later.
|
| CVE-2026-6057 |
|
Path Traversal in path-traversal (CVE-2026-6057)
path traversal in path-traversal (CVE-2026-6057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39848 |
|
Vulnerability in csrf (CVE-2026-39848)
vulnerability in csrf (CVE-2026-39848). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.0` or later.
|
| CVE-2026-21904 |
|
Cross-Site Scripting (XSS) in juniper (CVE-2026-21904)
cross-site scripting in juniper (CVE-2026-21904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40089 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-40089)
SSRF in c (CVE-2026-40089). Confidential information can be exposed externally.
|
| CVE-2026-1584 |
|
Vulnerability in dos (CVE-2026-1584)
vulnerability in dos (CVE-2026-1584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40072 |
|
SSRF (Server-Side Request Forgery) in web3 (CVE-2026-40072)
SSRF in web3 (CVE-2026-40072). Risk of unauthorized operations or information disclosure. Exploitable via ``OffchainLookup``. Mitigation: upgrade to `8.0.0b2` or later.
|
| CVE-2026-39981 |
|
Path Traversal in agixt (CVE-2026-39981)
path traversal in agixt (CVE-2026-39981). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2025-62718 |
|
Vulnerability in axios (CVE-2025-62718)
vulnerability in axios (CVE-2025-62718). Confidential information can be exposed externally. Exploitable via ``NO_PROXY``. Mitigation: upgrade to `0.31.0` or later.
|
| CVE-2026-39976 |
|
Authentication Bypass in laravel (CVE-2026-39976)
authentication bypass in laravel (CVE-2026-39976). Confidential information can be exposed externally. Mitigation: upgrade to `13.7.1` or later.
|
| CVE-2026-4878 |
|
Vulnerability in privilege-escalation (CVE-2026-4878)
vulnerability in privilege-escalation (CVE-2026-4878). Successful exploitation can lead to full system takeover.
|
| CVE-2025-70365 |
|
Cross-Site Scripting (XSS) in c (CVE-2025-70365)
cross-site scripting in c (CVE-2025-70365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4112 |
|
SQL Injection in sqli (CVE-2026-4112)
SQL injection in sqli (CVE-2026-4112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34185 |
|
SQL Injection in sqli (CVE-2026-34185)
SQL injection in sqli (CVE-2026-34185). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5837 |
|
Vulnerability in sqli (CVE-2026-5837)
vulnerability in sqli (CVE-2026-5837). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5835 |
|
Cross-Site Scripting (XSS) in CVE-2026-5835 (CVE-2026-5835)
cross-site scripting in CVE-2026-5835 (CVE-2026-5835). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5836 |
|
Cross-Site Scripting (XSS) in CVE-2026-5836 (CVE-2026-5836)
cross-site scripting in CVE-2026-5836 (CVE-2026-5836). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5834 |
|
Cross-Site Scripting (XSS) in CVE-2026-5834 (CVE-2026-5834)
cross-site scripting in CVE-2026-5834 (CVE-2026-5834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4429 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4429)
cross-site scripting in wordpress (CVE-2026-4429). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5357 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5357)
cross-site scripting in wordpress (CVE-2026-5357). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3574 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3574)
cross-site scripting in wordpress (CVE-2026-3574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3568 |
|
Vulnerability in wordpress (CVE-2026-3568)
vulnerability in wordpress (CVE-2026-3568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5828 |
|
Vulnerability in sqli (CVE-2026-5828)
vulnerability in sqli (CVE-2026-5828). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5829 |
|
Vulnerability in sqli (CVE-2026-5829)
vulnerability in sqli (CVE-2026-5829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4326 |
|
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate...
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check...
|
| CVE-2026-5827 |
|
Vulnerability in sqli (CVE-2026-5827)
vulnerability in sqli (CVE-2026-5827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5826 |
|
Cross-Site Scripting (XSS) in CVE-2026-5826 (CVE-2026-5826)
cross-site scripting in CVE-2026-5826 (CVE-2026-5826). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5825 |
|
Cross-Site Scripting (XSS) in CVE-2026-5825 (CVE-2026-5825)
cross-site scripting in CVE-2026-5825 (CVE-2026-5825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5823 |
|
Vulnerability in sqli (CVE-2026-5823)
vulnerability in sqli (CVE-2026-5823). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5824 |
|
Vulnerability in sqli (CVE-2026-5824)
vulnerability in sqli (CVE-2026-5824). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5814 |
|
Vulnerability in sqli (CVE-2026-5814)
vulnerability in sqli (CVE-2026-5814). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5813 |
|
Vulnerability in c (CVE-2026-5813)
vulnerability in c (CVE-2026-5813). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3438 |
|
Cross-Site Scripting (XSS) in CVE-2026-3438 (CVE-2026-3438)
cross-site scripting in CVE-2026-3438 (CVE-2026-3438). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1092 |
|
Vulnerability in dos (CVE-2026-1092)
vulnerability in dos (CVE-2026-1092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1101 |
|
Vulnerability in dos (CVE-2026-1101)
vulnerability in dos (CVE-2026-1101). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12664 |
|
Vulnerability in dos (CVE-2025-12664)
vulnerability in dos (CVE-2025-12664). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5810 |
|
Cross-Site Scripting (XSS) in CVE-2026-5810 (CVE-2026-5810)
cross-site scripting in CVE-2026-5810 (CVE-2026-5810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40035 |
|
Vulnerability in dfir-unfurl (CVE-2026-40035)
vulnerability in dfir-unfurl (CVE-2026-40035). Confidential information can be exposed externally. Exploitable via ``debug``.
|
| CVE-2026-5711 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5711)
cross-site scripting in wordpress (CVE-2026-5711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5806 |
|
Cross-Site Scripting (XSS) in CVE-2026-5806 (CVE-2026-5806)
cross-site scripting in CVE-2026-5806 (CVE-2026-5806). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5808 |
|
Cross-Site Scripting (XSS) in CVE-2026-5808 (CVE-2026-5808)
cross-site scripting in CVE-2026-5808 (CVE-2026-5808). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40036 |
|
Vulnerability in dfir-unfurl (CVE-2026-40036)
vulnerability in dfir-unfurl (CVE-2026-40036). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260405` or later.
|
| CVE-2026-40028 |
|
Cross-Site Scripting (XSS) in yamato-security (CVE-2026-40028)
cross-site scripting in yamato-security (CVE-2026-40028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40027 |
|
Path Traversal in path-traversal (CVE-2026-40027)
path traversal in path-traversal (CVE-2026-40027). Confidential information can be exposed externally.
|
| CVE-2026-40024 |
|
Path Traversal in path-traversal (CVE-2026-40024)
path traversal in path-traversal (CVE-2026-40024). Confidential information can be exposed externally.
|
| CVE-2026-5805 |
|
Vulnerability in c (CVE-2026-5805)
vulnerability in c (CVE-2026-5805). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5436 |
|
Path Traversal in wordpress (CVE-2026-5436)
path traversal in wordpress (CVE-2026-5436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5451 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5451)
cross-site scripting in wordpress (CVE-2026-5451). Risk of unauthorized operations or information disclosure.
|